Google Apps has become an increasingly popular set of productivity tools for business users, but the discovery of a flaw that could allow cybercriminals to conduct email spoofing using the admin console may have some early adopters concerned.

Security researchers Patrik Fehrenbach and Behrouz Sadeghipour explained in a blog post how they found an imperfection that involves using a Google Apps domain name that hasn’t already been claimed by a customer. In a series of tests, they were able to commit email spoofing — in other words, sending out messages through someone else’s Google Apps domain.

Although there is no evidence cybercriminals have exploited the flaw, it represents a particularly dangerous threat. In many attempts to spread malware via email, cybercriminals are often forced to create phony or suspicious-looking addresses that may not look enough like the real thing. In this case, the Google Apps admin tool could let anyone impersonate a legitimate organization much more effectively if, for example, they were committing phishing attacks.

Likely to underscore the severity of the threat, researchers used the flaw to commit email spoofing from domains related to Google itself. ZDNet reported that “[email protected]” and “[email protected]” were among the variations used. It’s little wonder Google wasn’t just quick to fix the problem, but to award the researchers a prize of $500.

Unfortunately, this isn’t the first security issue involving Google’s business tools. As SecurityWeek pointed out, the admin console has also been plagued by a cross-scripting vulnerability as recently as two months ago. The fact that Google fixed the email spoofing problem by simply adding “[email protected]” for unverified domains shows how simple some of these attacks are becoming.

It’s also rather ironic that, in December, Google introduced a series of enterprise security features for Google Apps. These included a Devices and Activities Dashboard, as explained by the Financial Post, that would help administrators monitor for questionable behavior. Nevertheless, one might argue that hijacking email domains could be even worse.

Over the next week, Google may offer a more comprehensive fix for email spoofing, The Hacker News said. In the meantime, it’s always best to consider that, if an email message looks a little off, it probably is.

Image Source: Flickr

More from

Vulnerability resolution enhanced by integrations

2 min read - Why speed is of the essence in today's cybersecurity landscape? How are you quickly achieving vulnerability resolution?Identifying vulnerabilities should be part of the daily process within an organization. It's an important piece of maintaining an organization’s security posture. However, the complicated nature of modern technologies — and the pace of change — often make vulnerability management a challenging task.In the past, many organizations had to support manual integration work to get different security systems to ‘talk’ to each other. As…

How I got started: SIEM engineer

2 min read - As careers in cybersecurity become increasingly more specialized, Security Information and Event Management (SIEM) engineers are playing a more prominent role. These professionals are like forensic specialists but are also on the front lines protecting sensitive information from the relentless onslaught of cyber threats. SIEM engineers meticulously monitor, analyze and manage security events and incidents within an organization. They leverage SIEM tools to aggregate and correlate data, enabling them to detect anomalies, identify potential threats and respond swiftly to security…

Tequila OS 2.0: The first forensic Linux distribution in Latin America

3 min read - Incident response teams are stretched thin, and the threats are only intensifying. But new tools are helping bridge the gap for cybersecurity pros in Latin America.IBM Security X-Force Threat Intelligence Index 2023 found that 12% of the security incidents X-force responded to were in Latin America. In comparison, 31% were in the Asia-Pacific, followed by Europe with 28%, North America with 25% and the Middle East with 4%. In the Latin American region, Brazil had 67% of incidents that X-Force…

Cost of a data breach 2023: Geographical breakdowns

4 min read - Data breaches can occur anywhere in the world, but they are historically more common in specific countries. Typically, countries with high internet usage and digital services are more prone to data breaches. To that end, IBM’s Cost of a Data Breach Report 2023 looked at 553 organizations of various sizes across 16 countries and geographic regions, and 17 industries. In the report, the top five costs of a data breach by country or region (measured in USD millions) for 2023…